UnitedHealth admits breach could 'cover substantial proportion of people in America'
- Reference: 1713875415
- News link: https://www.theregister.co.uk/2024/04/23/unitedhealth_admits_breach_substantial/
- Source link:
"Based on the initial targeted data sampling to date, the company has found files containing protected health information and personally identifiable information, which could cover a substantial proportion of people in America," it [1]said in a statement.
"To date, the company has not seen evidence of exfiltration of materials such as doctors' charts or full medical histories among the data," UnitedHealth added.
[2]
The ransomware attack, which [3]began in February , impacted hospital and pharmacies that use the insurance and billing services of UnitedHeath across the US for weeks. Electronic prescriptions came [4]back online in early March .
[5]
[6]
The exact number of people affected was not mentioned. Given the "ongoing nature and complexity of the data review," the insurance giant estimates it will likely take third party experts "several months of continued analysis" to comb through enough information to "identify and notify impacted customers and individuals."
An affiliate of [7]ALPHV claimed responsibility for the breach. According to a report in the [8]Wall Street Journal yesterday, the criminal crew got into Change Healthcare's network via pilfered credentials for a tech system that permits remote access to its network. The criminal gang spent more than a week inside until they unleashed the ransomware and stole data from the systems.
[9]
A spokesperson at UnitedHealth told [10]TechCrunch that a ransom had been paid "as part of the company's commitment to do all it could to protect patient data from disclosure." The amount was not specified but it was understood to be around [11]$22 million .
RansomHub, another criminal crew, [12]recently released what is believed to be personal patient data from the hack and itself demanded a ransom to stop it leaking more. It claimed that it was storing the data, and not ALPHV.
[13]185K people's sensitive data in the pits after ransomware raid on Cherry Health
[14]Change Healthcare faces second ransomware dilemma weeks after ALPHV attack
[15]White House and lawmakers increase pressure on UnitedHealth to ease providers' pain
[16]Change Healthcare registers pulse after crippling ransomware attack
UnitedHealth and its external cyber specialists claim they are still "monitoring" the dark web to ascertain if more data has been published online. The company says it saw 22 screenshots, "allegedly from exfiltrated files," some of which contained protected health information and personally identifiable information, that it says was posted on the dark web for roughly one week by miscreants, but claims it has spotted nothing since.
The cost of the saga to the org is currently pegged at [17]$870 million for calendar Q1 and could stretch to $1.6 billion for the year, UnitedHealth confirmed last week. ®
Get our [18]Tech Resources
[1] https://www.unitedhealthgroup.com/newsroom/2024/2024-04-22-uhg-updates-on-change-healthcare-cyberattack.html
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZifbIokOFE-d7Tbaotn5MgAAAJA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2024/02/22/change_healthcare_outage/
[4] https://www.theregister.com/2024/03/08/change_healthcare_restores_first_system/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZifbIokOFE-d7Tbaotn5MgAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZifbIokOFE-d7Tbaotn5MgAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2024/02/29/alphv_change_healthcare/
[8] https://www.wsj.com/articles/change-healthcare-hackers-broke-in-nine-days-before-ransomware-attack-7119fdc6
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZifbIokOFE-d7Tbaotn5MgAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://techcrunch.com/2024/04/22/unitedhealth-change-healthcare-hackers-substantial-proportion-americans/
[11] https://www.theregister.com/2024/03/04/alphv_ransom_payment/
[12] https://www.theregister.com/2024/04/08/change_healthcare_ransomware/
[13] https://www.theregister.com/2024/04/18/ransomware_cherry_health/
[14] https://www.theregister.com/2024/04/08/change_healthcare_ransomware/
[15] https://www.theregister.com/2024/03/12/white_house_pressures_unitedhealth/
[16] https://www.theregister.com/2024/03/08/change_healthcare_restores_first_system/
[17] https://www.theregister.com/2024/04/16/change_healthcares_ransomware_attack_has/
[18] https://whitepapers.theregister.com/
The cost of the saga to the org is currently pegged at $870 million for calendar Q1 and could stretch to $1.6 billion for the year, UnitedHealth confirmed last week. ®
I'd love to know if Change Healthcare's geeks had tried to get and were turned down for money to bring the company's infrastructure up to date. If that is the case, then I'd like to know even more if the sum requested was less than $870M
They may have proposed procedures which could have involved trading a smidge of inconvenience for security. Nothing like the inconvenience caused to all the victims, of course.
blackmailed twice
Pay the ransom then the blackmailers return for a double dip.
well I never.
Things are at least improving about the PR response. It's not claimed to be just a few.
What about one-time credentials?
" the criminal crew got into Change Healthcare's network via pilfered credentials for a tech system that permits remote access to its network "
As a really basic protection, any remote access for technical management should always use connection source validation and out of band generated one-time credentials so they're useless to an adversary. This is so fundamental! It amazes me that any business fails to implement it. Unless of course this breach really resulted from compromise of an already authenticated current session, which is a whole different issue. And then of course there's the question of whether the network segregation was adequate.
But as Major General Jonathan Shaw, late head of cyber security at the UK MoD famously stated “ ...about 80 per cent of our cyber problems are caused by what I call poor cyber hygiene. ”